Privacy Policy

Version 1.0 — Effective date: 1 April 2026

Compliant with UAE Federal Decree-Law No. 45 of 2021 (PDPL)

1. Who we are

Doobitech ("we", "us", "our") is a SaaS platform operated by a DED-licensed business in Dubai, United Arab Emirates. We provide WhatsApp-based order management software for laundry and dry-cleaning businesses.

Contact: fender.helper@gmail.com

2. What data we collect

From Shop Owners (B2B customers)

  • Name, email address, password (hashed)
  • Shop name, WhatsApp business number
  • Trade license document (PDF or image)
  • IP address at time of Terms acceptance
  • Billing information (processed by Stripe — we do not store card numbers)

From End Customers (laundry customers)

  • WhatsApp phone number
  • Name (if provided)
  • Pickup address and GPS coordinates
  • Order history and services selected
  • Preferred language
  • Star ratings and comments (if submitted)

Automatically collected

  • WhatsApp message logs (sent and received)
  • Session data in Redis (30-minute TTL, auto-deleted)
  • Usage logs and error reports

3. How we use your data

  • To provide and operate the Doobitech platform
  • To process orders and send WhatsApp notifications
  • To verify trade licenses and maintain compliance
  • To process subscription payments via Stripe
  • To send service announcements and billing alerts
  • To improve platform performance and fix errors
  • To comply with UAE legal obligations

We do not sell, rent, or share personal data with third parties for marketing purposes.

4. Legal basis for processing

Under UAE PDPL, we process personal data on the following bases:

  • Contract performance — processing necessary to provide the subscription service
  • Legal obligation — trade license verification, VAT records, PDPL compliance
  • Legitimate interest — platform security, fraud prevention, error monitoring
  • Consent — marketing communications (opt-in only)

5. Data storage and security

5.1 Data is stored on Supabase (PostgreSQL) hosted in EU West 2 (London, UK) and Upstash Redis hosted in EU West 1.

5.2 All data is encrypted in transit (TLS 1.2+) and at rest.

5.3 Passwords are hashed using bcrypt and never stored in plain text.

5.4 Access to production data is restricted to authorised Doobitech personnel only.

5.5 Row-Level Security (RLS) is enforced at the database level — each shop can only access its own data.

6. Data retention

Data typeRetention period
Order records5 years (UAE commercial law)
WhatsApp message logs12 months
Redis session data30 minutes (auto-deleted)
Trade license documentsDuration of account + 1 year
Billing records7 years (UAE tax law)
Deleted account data30 days after deletion request

7. Third-party services

Supabase

EU West 2 (London)

Database, authentication, file storage

360dialog

EU

WhatsApp Business API messaging

Stripe

USA (EU data region)

Payment processing (B2B subscriptions)

Vercel

Global CDN

Application hosting and deployment

Upstash

EU West 1

Session state and rate limiting

8. Your rights under UAE PDPL

Under Federal Decree-Law No. 45 of 2021, you have the following rights:

  • Right of access — request a copy of your personal data
  • Right to rectification — correct inaccurate data
  • Right to erasure — request deletion of your data
  • Right to restrict processing — limit how we use your data
  • Right to data portability — receive your data in a structured format
  • Right to object — object to processing based on legitimate interest

To exercise any of these rights, email fender.helper@gmail.com. We will respond within 30 days as required by UAE PDPL.

9. Data breach notification

In the event of a personal data breach, Doobitech will notify the UAE Data Office and affected individuals as soon as possible and in accordance with the timelines required by UAE PDPL.

10. WhatsApp data notice

When customers interact with a shop's WhatsApp bot powered by Doobitech, the first message they receive includes a notice that their data will be processed to handle their laundry order. By continuing to interact with the bot, customers acknowledge this processing.

11. Children's data

Doobitech does not knowingly collect data from individuals under the age of 18. If we become aware that we have collected data from a minor, we will delete it immediately.

12. Changes to this policy

We may update this Privacy Policy periodically. We will notify you via email and WhatsApp at least 14 days before material changes take effect. The current version and effective date are always shown at the top of this page.

13. Contact us

For any privacy-related questions, data requests, or complaints:

Email: fender.helper@gmail.com

We aim to respond to all privacy requests within 5 business days.